DomainDrift details
Back to DomainDriftScanning Methodology
DomainDrift is not a web crawler. It is a DNS and infrastructure-metadata scanner. DomainDrift does not crawl websites, index page content, follow links, or traverse URL paths.
DomainDrift collects publicly available infrastructure metadata: DNS records, TLS certificate data, domain registration information, and the HTTP response status from a single lightweight probe to a domain's root. Every observation is Ed25519-signed at the moment of collection, producing a tamper-evident provenance receipt.
HTTP requests to target domains
HEAD /Single liveness probe recording HTTP status and response headers. Falls back to GET only if the server returns 405 Method Not Allowed.GET /robots.txtCollected as a data point for AI crawler policy analysis. DomainDrift reads this file to report which AI user-agents a domain blocks. This is observational. DomainDrift records the contents but does not use robots.txt as a crawl gate, because DomainDrift does not crawl.DomainDrift does not
External metadata APIs
These requests go to third-party public APIs, not to the target domain.
Identification
DomainDrift-DNS-Intelligence/0.5 (+https://domaindrift.io)HTTPS only. Maximum 3 redirect hops. 3 to 5 second timeouts per request.Opt-out
Domain operators can request exclusion from DomainDrift scanning by emailing inquiries@drm3.io with the domain name. Opt-out requests are processed within 7 business days.
Don't see your domain?
Submit your domain for inclusion in the DomainDrift scanning catalog. We review every submission and follow up within 7 business days.
Live Provenance
Every scan produces Ed25519-signed receipts across five observation planes. Each receipt is independently verifiable against the published keys, on your own machine.
Live from the DomainDrift scanning network
